Skip to content
← All services

Penetration testing service

Secure Code Review

Manual review of the source, following the data from entry point to sink. Finds the classes of flaw that black-box testing structurally cannot reach.

What the test covers

  • Authentication and authorisation implementation
  • Input handling and output encoding across all trust boundaries
  • Cryptographic implementation and key handling
  • Secrets in source and in build configuration
  • Dependency review for known-vulnerable components
  • Business logic paths that are not reachable from the interface

Deliverables

  • Executive summary
  • Findings referenced to file and line, with the vulnerable path traced
  • Prioritised remediation roadmap
  • One retest round against the fixes

Out of scope

  • Code quality and performance review
  • Full automated SAST licensing